{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/baota--11.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aapanel:baota:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-101008"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BaoTa (\u003c= 11.8.0)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","rce","command-injection","remote-code-execution","vulnerability","linux","webserver","aaPanel"],"_cs_type":"threat","_cs_vendors":["aaPanel"],"content_html":"\u003cp\u003eaaPanel BaoTa versions up to 11.8.0 contain a critical command injection vulnerability in the merge_split_file function, located within the file /www/server/panel/class/files.py. The vulnerability exists within the File Merge Handler component. An unauthenticated remote attacker can exploit this by sending a specially crafted request containing a malicious split_file_path argument. Because the application fails to properly sanitize this input before passing it to the underlying system shell, it allows for the execution of arbitrary commands with the privileges of the web application user. This flaw is publicly disclosed and currently lacks a vendor-provided patch. Defenders should treat this as a high-priority exposure, as public exploit code increases the likelihood of active exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the target server. Given that aaPanel is a web hosting control panel, successful compromise typically yields administrative control over the underlying Linux OS and all hosted web content. This allows for data exfiltration, service disruption, and the potential use of the server as a pivot point within the infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict external network access to the aaPanel management interface immediately, ensuring it is not reachable from the public internet.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to inspect HTTP requests for shell metacharacters (e.g., ;, |, \u0026amp;\u0026amp;, `) within the split_file_path parameter targeting the /www/server/panel/class/files.py file path.\u003c/li\u003e\n\u003cli\u003eMonitor system audit logs for unexpected processes spawned by the web server user (typically www or www-data).\u003c/li\u003e\n\u003cli\u003eAudit the server for evidence of post-exploitation activity, such as the creation of unauthorized web shells or persistence mechanisms.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T08:49:44Z","date_published":"2026-09-28T08:49:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aapanel-command-injection/","summary":"An unauthenticated remote command injection vulnerability in the aaPanel BaoTa File Merge Handler allows attackers to execute arbitrary system commands via the split_file_path parameter.","title":"Command Injection in aaPanel BaoTa via File Merge Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-aapanel-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - BaoTa (\u003c= 11.8.0)","version":"https://jsonfeed.org/version/1.1"}